5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-23467
Media Control Panel Web
8.1
HIGH
EPSS
0.3%
2023 CWE-79 1 PoC

Media CP Media Control Panel latest version. Reflected XSS possible through unspecified endpoint.

CVE-2023-25734
Firefox Windows
8.1
HIGH
EPSS
0.2%
2023 2 PoCs

After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.<br>*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

CVE-2023-50807
Software Genérico General
8.1
HIGH
EPSS
0.3%
2023 2 PoCs

A vulnerability was discovered in Samsung Wearable Processor and Modems with versions Exynos 9110, Exynos Modem 5123, Exynos Modem 5300 that allows an out-of-bounds write in the heap in 2G (no auth).

CVE-2023-23464
Media Control Panel General
8.1
HIGH
EPSS
0.2%
2023 1 PoC

Media CP Media Control Panel latest version. A Permissive Flash Cross-domain Policy may allow information disclosure.

CVE-2023-34217
TN-5900 Series General
8.1
HIGH
EPSS
0.2%
2023 CWE-22 1 PoC

TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command-injection vulnerability. This vulnerability stems from insufficient input validation in the certificate-delete function, which could potentially allow malicious users to delete arbitrary files.

CVE-2023-46725
foodcoopshop Web
8.1
HIGH
EPSS
0.2%
2023 CWE-918 1 PoC

FoodCoopShop is open source software for food coops and local shops. Versions starting with 3.2.0 prior to 3.6.1 are vulnerable to server-side request forgery. In the Network module, a manufacturer account can use the `/api/updateProducts.json` endpoint to make the server send a request to an arbitrary host. This means that the server can be used as a proxy into the internal network where the server is. Furthermore, the checks on a valid image are not adequate, leading to a time of check time of use issue. For example, by using a custom server that returns 200 on HEAD requests, then return a v

CVE-2023-43608
Buildroot General
8.1
HIGH
EPSS
0.1%
2023 CWE-494 2 PoCs

A data integrity vulnerability exists in the BR_NO_CHECK_HASH_FOR functionality of Buildroot 2023.08.1 and dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.

CVE-2023-47257
Software Genérico General
8.1
HIGH
EPSS
6.4%
2023 1 PoC

ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.

CVE-2023-39372
Softswitch Web
8.1
HIGH
EPSS
0.1%
2023 CWE-352 1 PoC

StarTrinity Softswitch version 2023-02-16 - Multiple CSRF (CWE-352)

CVE-2023-0787
thorsten/phpmyfaq Web
8.1
HIGH
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository thorsten/phpmyfaq prior to 3.1.11.

CVE-2023-44857
Software Genérico General
8.1
HIGH
EPSS
0.4%
2023 1 PoC

An issue in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to the sub_21D24 function in the acu_web component.

CVE-2023-20938
Android General
8.1
HIGH
EPSS
0.2%
2023 1 PoC

In binder_transaction_buffer_release of binder.c, there is a possible use after free due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-257685302References: Upstream kernel

CVE-2023-26067
Software Genérico General ⚡ nuclei
8.1
HIGH
EPSS
93.0%
2023 2 PoCs

Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).

CVE-2023-5905
DeMomentSomTres WordPress Export Posts With Images Web Windows
8.1
HIGH
EPSS
0.2%
2023 1 PoC

The DeMomentSomTres WordPress Export Posts With Images WordPress plugin through 20220825 does not check authorization of requests to export the blog data, allowing any logged in user, such as subscribers to export the contents of the blog, including restricted and unpublished posts, as well as passwords of protected posts.

CVE-2023-29325
Windows 10 Version 1809 Windows
8.1
HIGH
EPSS
22.1%
2023 CWE-416 2 PoCs

Windows OLE Remote Code Execution Vulnerability

CVE-2023-4220
Chamilo Web ⚡ nuclei
8.1
HIGH
EPSS
93.2%
2023 CWE-434 28 PoCs

Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via uploading of web shell.

CVE-2023-5397
Experion Server General
8.1
HIGH
EPSS
0.3%
2023 CWE-20 1 PoC

Server receiving a malformed message to create a new connection could lead to an attacker performing remote code execution or causing a failure. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-36809
Kiwi Web
8.1
HIGH
EPSS
0.7%
2023 CWE-79 1 PoC

Kiwi TCMS, an open source test management system allows users to upload attachments to test plans, test cases, etc. Versions of Kiwi TCMS prior to 12.5 had introduced changes which were meant to serve all uploaded files as plain text in order to prevent browsers from executing potentially dangerous files when such files are accessed directly. The previous Nginx configuration was incorrect allowing certain browsers like Firefox to ignore the `Content-Type: text/plain` header on some occasions thus allowing potentially dangerous scripts to be executed. Additionally, file upload validators and pa

CVE-2023-28244
Windows Server 2019 Windows
8.1
HIGH
EPSS
6.0%
2023 CWE-327 1 PoC

Windows Kerberos Elevation of Privilege Vulnerability

CVE-2023-3009
nilsteampassnet/teampass Web
8.1
HIGH
EPSS
1.5%
2023 CWE-79 2 PoCs

Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.